cbcvebase.
CVE-2012-0738
published 2012-12-28

CVE-2012-0738: IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows…

medium5.8CVSS 3.1
AVNACMAuNCPIPAN
IBM Security AppScan Enterprise before 8.6.0.2 and Rational Policy Tester before 8.5.0.3 do not validate X.509 certificates during scanning, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary certificate.

Affected

25 ranges
VendorProductVersion rangeFixed in
ibmrational_policy_tester<= 8.5.0.2
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmrational_policy_tester
ibmsecurity_appscan<= 8.6.0.1
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan
ibmsecurity_appscan